Search CVE reports
11 – 20 of 54252 results
A path traversal vulnerability exists in the unzip_http RemoteZipFile extract functionality of VisiData (version(s): dev (commit 38b21f78)). A specially crafted .zip file can lead to arbitrary file write. An attacker can provide a...
1 affected package
visidata
| Package | 22.04 LTS |
|---|---|
| visidata | Needs evaluation |
A flaw was found in flatpak-builder. This vulnerability allows an attacker to cause information disclosure by convincing a user or continuous integration (CI) system to process a crafted build manifest. By specifying local file...
1 affected package
flatpak-builder
| Package | 22.04 LTS |
|---|---|
| flatpak-builder | Needs evaluation |
In OpenStack Zaqar before 23.0.1, the WebSocket transport fails to bind the project identifier in subsequent requests to the project authenticated by the Keystone token. An authenticated user with a valid token for one project may...
1 affected package
zaqar
| Package | 22.04 LTS |
|---|---|
| zaqar | Needs evaluation |
traverse (npm) versions 0.3.6 through 0.3.9, 0.4.0 through 0.4.6, 0.5.0 through 0.5.2, and 0.6.0 through 0.6.11 allow prototype pollution through set(). When the path passed to set() crosses a primitive value, the next path...
1 affected package
node-traverse
| Package | 22.04 LTS |
|---|---|
| node-traverse | Needs evaluation |
pgjdbc, the PostgreSQL JDBC Driver, versions 42.7.4 through 42.7.13 pads a value that is shorter than its declared length with bytes left in its send buffer instead of zeros, and the server stores those bytes as part of the value....
1 affected package
libpgjava
| Package | 22.04 LTS |
|---|---|
| libpgjava | Needs evaluation |
pgjdbc, the PostgreSQL JDBC Driver, versions 42.7.11 through 42.7.13 enforce no restriction when the requireAuth connection property excludes all six authentication methods the driver knows, for...
1 affected package
libpgjava
| Package | 22.04 LTS |
|---|---|
| libpgjava | Needs evaluation |
pgjdbc, the PostgreSQL JDBC Driver, versions 42.7.4 and 42.7.5 can send the previous contents of the GSS send buffer in place of the first part of a value on a connection with GSS encryption (gssEncMode=prefer or require), and the...
1 affected package
libpgjava
| Package | 22.04 LTS |
|---|---|
| libpgjava | Needs evaluation |
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.12 and 2.16.1, a proxied ws request is carried through CONNECT,...
1 affected package
async-http-client
| Package | 22.04 LTS |
|---|---|
| async-http-client | Needs evaluation |
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.12 and 2.16.1, WebSocketHandler.upgrade aborts a handshake...
1 affected package
async-http-client
| Package | 22.04 LTS |
|---|---|
| async-http-client | Needs evaluation |
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.12 and 2.16.1, Realm.Builder generates the HTTP Digest client nonce with...
1 affected package
async-http-client
| Package | 22.04 LTS |
|---|---|
| async-http-client | Needs evaluation |